Where security signals surface
Every thread carries a live sentiment score, and for security that’s a useful early-warning layer: a user who’s been phished or locked out reads as frustrated fast, and Magic Sentiment scores that from the conversation and rolls it up to a company average. Watch the low-scoring threads — they’re often the ones where something is actually wrong. Sentiment is also an escalation trigger. You can configure a low score to fire an automatic escalation and post a recap using a template your team defines, so a souring security thread routes to the right board or person without a human noticing it first.Sentiment analysis starts only after the customer has sent at least three messages, and the very first message is excluded — early frustration is normal in IT support. Treat the score as a trend signal on a live conversation, not a verdict on the first line.
Investigate with Super Magic — read is always safe
Super Magic is your investigator in the ticket. It reads freely — tickets, contacts, clients, and knowledge — and looking things up never changes anything, so you can dig without touching state. Open it while viewing a thread and it already has that ticket’s context.Act only with confirmation
When investigation turns into response, Super Magic switches modes — and this is the safety property to put in front of whoever reviews security at your company:- Every write action shows a Confirm action card first. Before anything changes, you see the exact action, a plain-language description, and every detail (which ticket, which status, which contact). Nothing runs until you click Confirm.
- Actions record under the individual member, never a faceless service account. When a responder confirms an escalation or note, the ticket history shows that person did it. Accountability holds end to end.
- Access is layered and admin-controlled. Write access is set to All members, Admins only, or a custom list, with a per-tool toggle on every action. Intents and Flows are always admin-only.
Take device action from the ticket — with NinjaOne
When a security thread needs a machine touched — reboot a compromised endpoint, restart a service, flip maintenance mode, reset an alert — NinjaOne connected to Super Magic lets you do it from the chat instead of pivoting to the RMM. Two properties make this safe to allow:- Device actions are writes, so they’re always behind a Confirm action card. Look-ups (device health, active alerts, recent activity, Windows services) are read-only; reboots, service restarts, maintenance mode, alert resets, and device approvals all confirm first.
- Each member acts under their own NinjaOne permissions. NinjaOne connects in two layers — an admin configures the workspace connection once, and every technician signs in with their own NinjaOne account. Super Magic can never do more on a device than that member could do signed into NinjaOne directly, so your existing NinjaOne role assignments keep enforcing.
NinjaOne for Super Magic is a limited release. Contact your Thread account team to enable it, then follow the two-layer setup on Connect NinjaOne to Super Magic.
Next
That’s how security work moves through the desk. Next: the data-handling and permissions story you’ll defend to clients and auditors.How Thread handles your data
Encryption, Magic AI privacy, sub-processors, IP allowlisting, and app permissions.